QID 730753

Date Published: 2023-03-21

QID 730753: Jenkins Multiple Security Vulnerabilities (SECURITY-3030, SECURITY-2120)

Jenkins is an open-source automation server written in Java. Jenkins helps to automate the non-human part of the software development process, with continuous integration and facilitating technical aspects of continuous delivery.

Affected versions:
Jenkins weekly up to and including 2.393
Jenkins LTS up to and including 2.375.3

Fixed Version:
Jenkins weekly should be updated to version 2.394
Jenkins LTS should be updated to version 2.375.4 or 2.387.1

QID Detection Logic (unauthenticated):
This QID checks for vulnerable version of Jenkins by sending a GET request to /login page and checking the version from the response received.

A successful exploit could be resulting in information disclosure or allowing attackers to perform denial of service attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.5 severity.
  • Solution
    Customers are advised to upgrade to latest Jenkins version
    For further details refer to Jenkins Security Advisory 2023-03-08
    Vendor References

    CVEs related to QID 730753

    Software Advisories
    Advisory ID Software Component Link
    Jenkins Security Advisory 2023-03-08 URL Logo www.jenkins.io/security/advisory/2023-03-08/